Skip to content

Going live

Everything to check before you take real payments, and after.

During the beta, test and live keys act on the same business: what you create with a test key shows up in your dashboard and in every list, like anything else, and every event's mode is live. On a live business a test key can read everything, but creating a payment, a checkout or a remainder, or changing what customers see or pay, answers 403 test_mode_unavailable, so a test key never moves real money or changes a live checkout. See test and live keys. Everything you tried while building is already in your live data, so review it before launch.

Before you launch

0 of 6 done

  • Swap your 402s_test_ key for a 402s_live_ one in your production environment, and restrict it to the resources your server uses.
  • simulate and POST /checkouts/{id}/mark-sent exist for testing. Make sure production code never sends either.
  • Subscribe to payment.succeeded, plus payment.underpaid and payment.needs_review if you handle them, verify every signature, and skip deliveries whose webhook-id you've already handled.
  • Point success_url and cancel_url at your production pages, on each payment or link. They must use https://; http:// works only for localhost and 127.0.0.1.
  • Pick your coins and networks, and turn cards on or off, in Settings, under Payments.
  • Run each simulated outcome through your integration, including underpaid and late transfers and declined cards.

Secure your account

0 of 5 done

  • Settings, under General. It signs in without a password or two-step code, and works only on 402pay's own site, so it can't be phished.
  • A password manager can make one for you. Change it in Settings if someone may have seen it; that signs out your other devices.
  • Settings, under General. Store the recovery codes somewhere other than your authenticator.
  • Password resets and security emails go to the address you sign in with, so protect that mailbox with two-step verification too.
  • Keep your recovery phrase and encryption password somewhere safe and offline. 402pay can't recover either one.

After launch

  • Watch webhook deliveries in the dashboard, and resend any that failed.
  • Handle underpaid and late payments as they come in, so no customer is left waiting.
  • Rotate a webhook secret or API key whenever someone with access leaves your team.